Personal context stays person-scoped.
Learning happens at the population level, and it never determines an individual's access.
SOC 2 Type 2
Independently audited controls. Additional frameworks are scoped to what your programs require, as part of pilot design.
Live posture in the trust centerThree data layers.
01
Person-scoped context
Identity, authorized attributes, and the task-specific information CASEY derives to complete the task.
never aggregated
02
Task and outcome record
What was requested, what was authorized, what happened, and what was verified.
never aggregated
03
De-identified cohort insight
What completed outcomes reveal about where services work and where gaps remain.
aggregates across people
What happens to a record.
- Created for an authorized task
- Used only within that purpose
- Minimum necessary crosses a boundary, with the person's authorization
- Outcome verified and recorded
- Expires under its retention rule
- Capability-scoped authority
- Every task runs with only the context and authority it requires. Read, write and submit permissions are scoped independently.
- Retention by purpose
- Task data remains only as long as the workflow needs it.
- Non-adverse use
- Cohort insight may improve provision, never deny, restrict or adversely price access.
- Minimum cohort threshold
- Set by re-identification risk. Nothing is released below it.
Security documentation.
Control-by-control detail on encryption, access, audit logging, retention and subprocessors is provided under our security documentation, with exact answers rather than summaries.